Comparison of Supervised and Unsupervised Learning for Detecting Anomalies in Network Traffic

被引:0
|
作者
McAndrew, Robert [1 ]
Hayne, Stephen [1 ]
Wang, Haonan [1 ]
机构
[1] Colorado State Univ, Ft Collins, CO 80523 USA
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Adversaries are always probing for vulnerable spots on the Internet so they can attack their target. By examining traffic at the firewall, we can look for anomalies that may represent these probes. To help select the right techniques we conduct comparisons of supervised and unsupervised machine learning on network flows to find sets of outliers flagged as potential threats. We apply Functional PCA and K-Means together versus Multilayer Perceptron on a real-world dataset of traffic prior to an NTP DDoS attack in January 2014; scanning activity was heightened during this pre-attack period. We partition data to evaluate detection powers of each technique and show that FPCA+Kmeans outperforms MLP. We also present a new variation of the circle plot for visualization of resulting outliers which we suggest excels at displaying multidimensional attributes of an individual IP's behavior over time. In small multiples, circle plots show a gestalt overview of traffic.
引用
收藏
页码:7136 / 7145
页数:10
相关论文
共 50 条
  • [1] A Method of Detecting Network Anomalies in Cyclic Traffic
    Harada, Shigeaki
    Kawahara, Ryoichi
    Mori, Tatsuya
    Kamiyama, Noriaki
    Hasegawa, Haruhisa
    Yoshino, Hideaki
    GLOBECOM 2008 - 2008 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, 2008,
  • [2] A Comparison of Supervised Machine Learning Algorithms for Classification of Communications Network Traffic
    Perera, Pramitha
    Tian, Yu-Chu
    Fidge, Colin
    Kelly, Wayne
    NEURAL INFORMATION PROCESSING, ICONIP 2017, PT I, 2017, 10634 : 445 - 454
  • [3] Detecting insurance fraud using supervised and unsupervised machine learning
    Debener, Joern
    Heinke, Volker
    Kriebel, Johannes
    JOURNAL OF RISK AND INSURANCE, 2023, 90 (03) : 743 - 768
  • [4] Detecting Amazon Bot Reviewers Using Unsupervised and Supervised Learning
    Wood, Brandon
    Slhoub, Khaled
    2022 IEEE WORLD AI IOT CONGRESS (AIIOT), 2022, : 303 - 310
  • [5] Detecting Anomalies in the Optical Layer Using Unsupervised Machine Learning
    Aladin, Sandra
    Wosinska, Lena
    Tremblay, Christine
    2024 OPTICAL FIBER COMMUNICATIONS CONFERENCE AND EXHIBITION, OFC, 2024,
  • [6] Unsupervised Learning Approach for Network Traffic Classification
    Abboud, Mario Bou
    Baala, Oumaya
    Drissit, Maroua
    Alliot, Sylvain
    20TH INTERNATIONAL WIRELESS COMMUNICATIONS & MOBILE COMPUTING CONFERENCE, IWCMC 2024, 2024, : 1155 - 1160
  • [7] A dynamic growing neural network for supervised or unsupervised learning
    Tian, Daxin
    Liu, Yanheng
    Wei, Da
    WCICA 2006: SIXTH WORLD CONGRESS ON INTELLIGENT CONTROL AND AUTOMATION, VOLS 1-12, CONFERENCE PROCEEDINGS, 2006, : 2886 - 2890
  • [8] Detecting anomalies in backbone network traffic: a performance comparison among several change detection methods
    Callegari, Christian
    Giordano, Stefano
    Pagano, Michele
    Pepe, Teresa
    INTERNATIONAL JOURNAL OF SENSOR NETWORKS, 2012, 11 (04) : 205 - 214
  • [9] Detecting abnormal DNS traffic using unsupervised machine learning
    Thi Quynh Nguyen
    Laborde, Romain
    Benzekri, Abdelmalek
    Qu'hen, Bruno
    2020 FOURTH CYBER SECURITY IN NETWORKING CONFERENCE (CSNET), 2020,
  • [10] WEAKLY SUPERVISED LEARNING FOR NETWORK TRAFFIC CLASSIFICATION
    Barut, Onur
    Zhang, Tong
    Li, Peilong
    2022 IEEE INTERNATIONAL CONFERENCE ON NETWORKING, ARCHITECTURE AND STORAGE (NAS), 2022, : 94 - 97